Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release

0
High
Published: 04/23/2026 (04/23/2026, 12:16:06 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21

Affected software

Affected versions
Red HatRed Hat multicluster global hubRed Hat multicluster global hub 1.5.0amd64registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:d91359dca7bc04e59f4f1c0d2e5c8a2ecfd92d3499636be065ec89e8ad2eac4f_amd64Red Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.3registry.redhat.io/rhtas/cosign-rhel9@sha256:b7599fcedc9a0777b71b048f7a5ca39371484483d25ddf33c4b4949a66d7eb78_amd64Multicluster Global HubMulticluster Global Hub 1.4.5registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:0465ebb0af8b850f3266a5e3400b269d420a6280cb6b883a606f9b588c102acc_amd64Red Hat QuayRed Hat Quay 3.18registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:6840404e712485db83fbfba9117eae50cf64c2a944eb58130c4455e138fa36ad_amd64registry.redhat.io/rhtas/createtree-rhel9@sha256:163edb41ea7f64afc8333ee14d4b28161f7017285afcca6ca12238732c77b98d_amd64registry.redhat.io/rhtas/rekor-backfill-redis-rhel9@sha256:35b00d6cc82f90b4577af0d2c15153e255d6bb946349bb85f175216cefad1d07_amd64Red Hat Quay 3.1registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:db1bd588d96d3eff25fce96b0e6d78d042b6041b0bb31a64f4683df65b3af5e3_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/26/2026, 01:48:52 UTC

Technical Analysis

Red Hat Multicluster Global Hub is a set of components that facilitate importing and managing multiple hub clusters from a single hub cluster. The security advisory RHSA-2026:21769 addresses multiple vulnerabilities in versions prior to 1.5.5, including CVE-2026-4427 and several others. These vulnerabilities span a variety of CWE categories such as race conditions, improper authentication, and memory issues. The update to version 1.5.5 includes security fixes, bug fixes, and updated container images to mitigate these issues. The advisory does not provide detailed CVSS scores but rates the overall impact as Important.

Potential Impact

The vulnerabilities affect the security posture of Red Hat Multicluster Global Hub by potentially allowing exploitation of issues related to authentication, memory management, race conditions, and other weaknesses as indicated by the CWE list. The exact impact of each vulnerability is not detailed, but the collective rating is Important, indicating a significant security concern that could affect cluster management operations if left unpatched.

Mitigation Recommendations

Red Hat has released version 1.5.5 of Multicluster Global Hub which includes security fixes for the identified vulnerabilities. Users should upgrade to version 1.5.5 or later to remediate these issues. No alternative mitigations or temporary fixes are indicated. Patch status is confirmed by the vendor advisory. Refer to the Red Hat Advanced Cluster Management for Kubernetes documentation and the official Red Hat advisory RHSA-2026:21769 for upgrade instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:11916
Cve Count
8
Additional Cves
["CVE-2026-25679","CVE-2026-27459","CVE-2026-29063","CVE-2026-29074","CVE-2026-32286","CVE-2026-33186","CVE-2026-34986"]
Cvss Version
null

Threat ID: 6a160956e29bf47b5061b0eb

Added to database: 05/26/2026, 20:57:58 UTC

Last enriched: 07/26/2026, 01:48:52 UTC

Last updated: 07/31/2026, 21:51:53 UTC

Views: 67

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/security/cve/CVE-2026-21728https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-27137https://access.redhat.com/security/cve/CVE-2026-27889https://access.redhat.com/security/cve/CVE-2026-29785https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-32283https://access.redhat.com/security/cve/CVE-2026-32285https://access.redhat.com/security/cve/CVE-2026-32286https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-33215https://access.redhat.com/security/cve/CVE-2026-33216https://access.redhat.com/security/cve/CVE-2026-33217https://access.redhat.com/security/cve/CVE-2026-33218https://access.redhat.com/security/cve/CVE-2026-33219https://access.redhat.com/security/cve/CVE-2026-33247https://access.redhat.com/security/cve/CVE-2026-33413https://access.redhat.com/errata/RHSA-2026:10130https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexhttps://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-4427https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:48085https://access.redhat.com/security/cve/CVE-2026-27459https://access.redhat.com/security/cve/CVE-2026-27962https://access.redhat.com/security/cve/CVE-2026-29074https://access.redhat.com/security/cve/CVE-2026-32590https://access.redhat.com/security/cve/CVE-2026-32591https://access.redhat.com/security/cve/CVE-2026-42039https://access.redhat.com/security/cve/CVE-2026-48526Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10126Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10131https://access.redhat.com/security/cve/CVE-2026-4800Canonical URLhttps://access.redhat.com/errata/RHSA-2026:11916https://access.redhat.com/security/cve/CVE-2026-29063Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses